Microsoft Updates And Notifications for May 2025

Discussion in 'other security issues & news' started by ronjor, May 1, 2025.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
    May 01, 2025

     
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
    May 1, 2025

     
  3. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,462
    Location:
    Ontario, Canada
    CVEs have been published or revised in the Security Update Guide

    May 2, 2025

    These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:

    CVE-2025-29825

    · Title: Microsoft Edge (Chromium-based) Spoofing Vulnerability

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 1, 2025

    · Last updated: May 1, 2025

    · Aggregate CVE severity rating: Low

    · Customer action required: Yes

    CVE-2025-4050

    · Title: Chromium: CVE-2025-4096 Heap buffer overflow in HTML

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 1, 2025

    · Last updated: May 1, 2025

    · Aggregate CVE severity rating:

    · Customer action required: Yes

    CVE-2025-4051

    · Title: Chromium: CVE-2025-4050 Out of bounds memory access in DevTools

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 1, 2025

    · Last updated: May 1, 2025

    · Aggregate CVE severity rating:

    · Customer action required: Yes

    CVE-2025-4052

    · Title: Chromium: CVE-2025-4051 Insufficient data validation in DevTools

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 1, 2025

    · Last updated: May 1, 2025

    · Aggregate CVE severity rating:

    · Customer action required: Yes

    CVE-2025-4096

    · Title: Chromium: CVE-2025-4052 Inappropriate implementation in DevTools

    · Version: 1.0

    · Reason for revision: Information published.

    · Originally released: May 1, 2025

    · Last updated: May 1, 2025

    · Aggregate CVE severity rating:

    Customer action required: Yes
     
  4. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
    May 6, 2025
     
  5. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
    May 8, 2025
     
  6. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,462
    Location:
    Ontario, Canada
    CVEs have been published or revised in the Security Update Guide
    May 8, 2025

    These common vulnerabilities and exposures (CVEs) were recently published or revised in the Microsoft Security Update Guide:

    CVE-2025-29813

    • Title: Azure DevOps Elevation of Privilege Vulnerability
    • Version: 1.0
    • Reason for revision: Information published.
    • Originally released: May 8, 2025
    • Last updated: May 8, 2025
    • Aggregate CVE severity rating: Critical
    • Customer action required: No
    CVE-2025-29827

    • Title: Azure Automation Elevation of Privilege Vulnerability
    • Version: 1.0
    • Reason for revision: Information published.
    • Originally released: May 8, 2025
    • Last updated: May 8, 2025
    • Aggregate CVE severity rating: Critical
    • Customer action required: No
    CVE-2025-29972

    • Title: Azure Storage Resource Provider Spoofing Vulnerability
    • Version: 1.0
    • Reason for revision: Information published.
    • Originally released: May 8, 2025
    • Last updated: May 8, 2025
    • Aggregate CVE severity rating: Critical
    • Customer action required: No
    CVE-2025-33072

    • Title: Microsoft msagsfeedback.azurewebsites.net Information Disclosure Vulnerability
    • Version: 1.0
    • Reason for revision: Information published.
    • Originally released: May 8, 2025
    • Last updated: May 8, 2025
    • Aggregate CVE severity rating: Critical
    • Customer action required: No
    CVE-2025-47732

    • Title: Microsoft Dataverse Remote Code Execution Vulnerability
    • Version: 1.0
    • Reason for revision: Information published.
    • Originally released: May 8, 2025
    • Last updated: May 8, 2025
    • Aggregate CVE severity rating: Critical
    • Customer action required: No
    CVE-2025-47733

    • Title: Microsoft Power Apps Information Disclosure Vulnerability
    • Version: 1.0
    • Reason for revision: Information published.
    • Originally released: May 8, 2025
    • Last updated: May 8, 2025
    • Aggregate CVE severity rating: Critical
    • Customer action required: No
     
  7. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,446
  8. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
  9. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
    May 14, 2025

     
  10. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,890
    Location:
    Texas
    May 15, 2025
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.